Red Hat Single Sign-On 7: path traversal
High8.1CVE-2026-74909 · Published Sep 16, 2026 · updated Sep 18, 2026
Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments. An authenticated user can use these encoded characters to trick the enforcer into applying a less restrictive security policy than intended, potentially gaining unauthorized access to sensitive administrative or private application endpoints.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.4.16 Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat build of Keycloak 26.6.7 Product | all versions | No fix yet |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
- www.cve.org/CVERecord?id=CVE-2026-74909
- nvd.nist.gov/vuln/detail/CVE-2026-74909
- access.redhat.com/errata/RHSA-2026:68276
- access.redhat.com/errata/RHSA-2026:68277
- access.redhat.com/errata/RHSA-2026:68278
- access.redhat.com/errata/RHSA-2026:68280
- access.redhat.com/security/cve/CVE-2026-74909
- bugzilla.redhat.com/show_bug.cgi?id=2517354
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | Red Hat Quay 3: attacker could inject arbitrary code | High8.0 | No fix yet |
| Sep 16 | Red Hat sequoia-openpgp. The: improper signature check | High7.4 | No fix yet |
| Sep 16 | Red Hat flightctl: race condition | Medium6.6 | No fix yet |
| Sep 16 | Red Hat first-broker-login flow: improper authentication | Medium5.3 | No fix yet |
| Sep 16 | Red Hat Data Grid 8: missing authorization | High7.2 | No fix yet |
| Sep 16 | Red Hat build of Keycloak: resource exhaustion | High7.5 | No fix yet |